System and Method for Controlling Comments in a Collaborative Document
    1.
    发明申请
    System and Method for Controlling Comments in a Collaborative Document 有权
    在协作文件中控制注释的系统和方法

    公开(公告)号:US20090129596A1

    公开(公告)日:2009-05-21

    申请号:US11941250

    申请日:2007-11-16

    IPC分类号: H04L9/14 G06F17/21

    CPC分类号: G06F17/241

    摘要: A system, method, and program product is provided that operates when opening a word processing document that includes document content inserted at various insertion points within the document. The document is opened by a user that corresponds to a particular user identifier. The comments included in the document include recipient identifiers. A first set of comments are selected where the user's identifier is included in the recipient identifiers of the corresponding comments, and a second set of comments are selected where the user's identifier is not included in the recipient identifiers of the corresponding comments. The word processor displays the first set of comments at their respective insertion points within the document content and does not present the second set of comments.

    摘要翻译: 提供了一种系统,方法和程序产品,其在打开包含在文档中的各种插入点处插入的文档内容的文字处理文档时操作。 文档由与特定用户标识符相对应的用户打开。 文档中包含的注释包括收件人标识符。 选择第一组注释,其中用户的标识符被包括在相应注释的接收者标识符中,并且选择第二组注释,其中用户的标识符不包括在相应注释的接收者标识符中。 文字处理器在文档内容中的各自的插入点处显示第一组注释,并且不显示第二组注释。

    System and method for controlling comments in a collaborative document
    2.
    发明授权
    System and method for controlling comments in a collaborative document 有权
    用于控制协作文档中的注释的系统和方法

    公开(公告)号:US07950064B2

    公开(公告)日:2011-05-24

    申请号:US11941250

    申请日:2007-11-16

    IPC分类号: G06F7/04

    CPC分类号: G06F17/241

    摘要: A system, method, and program product is provided that operates when opening a word processing document that includes document content inserted at various insertion points within the document. The document is opened by a user that corresponds to a particular user identifier. The comments included in the document include recipient identifiers. A first set of comments are selected where the user's identifier is included in the recipient identifiers of the corresponding comments, and a second set of comments are selected where the user's identifier is not included in the recipient identifiers of the corresponding comments. The word processor displays the first set of comments at their respective insertion points within the document content and does not present the second set of comments.

    摘要翻译: 提供了一种系统,方法和程序产品,其在打开包含在文档中的各种插入点处插入的文档内容的文字处理文档时操作。 文档由与特定用户标识符相对应的用户打开。 文档中包含的注释包括收件人标识符。 选择第一组注释,其中用户的标识符被包括在相应注释的接收者标识符中,并且选择第二组注释,其中用户的标识符不包括在相应注释的接收者标识符中。 文字处理器在文档内容中的各自的插入点处显示第一组注释,并且不显示第二组注释。

    Controlling a GUI display for a plug-in
    3.
    发明授权
    Controlling a GUI display for a plug-in 失效
    控制插件的GUI显示

    公开(公告)号:US07426713B2

    公开(公告)日:2008-09-16

    申请号:US10815214

    申请日:2004-03-31

    IPC分类号: G06F9/44

    CPC分类号: G06F9/445 G06F9/451

    摘要: Methods, systems, and computer program products are provided for controlling a GUI display for a plug-in in an application supporting plug-ins. Embodiments include receiving, at run time, in the application from the plug-in a request to display a GUI object; responsive to the request, retrieving an XML representation of the GUI object; and displaying the GUI object in dependence upon the retrieved XML representation of the GUI object. Typical embodiments also include receiving from the plug-in a request to retrieve user input responsive to the GUI object; and returning to the plug-in responsive user input.

    摘要翻译: 提供了方法,系统和计算机程序产品,用于控制支持插件的应用程序中插件的GUI显示。 实施例包括在运行时在应用程序中从插件接收显示GUI对象的请求; 响应于该请求,检索GUI对象的XML表示; 以及根据所检索的GUI对象的XML表示来显示GUI对象。 典型实施例还包括从插件接收响应于GUI对象检索用户输入的请求; 并返回到插件响应用户输入。

    Secure audit log access for federation compliance
    4.
    发明授权
    Secure audit log access for federation compliance 有权
    安全审核日志访问,以实现联盟合规性

    公开(公告)号:US08136146B2

    公开(公告)日:2012-03-13

    申请号:US11619728

    申请日:2007-01-04

    IPC分类号: H04L29/06

    摘要: A computer implemented method, data processing system, and computer program product for allowing limited access to a federation partner's audit logs in a secure, controlled manner, for the purposes of compliance demonstration. A request for audit data is received by a partner in the federated environment. The partner validates the request and requests a local report using local parameters against a local audit log store. The partner then builds a response based on the local report.

    摘要翻译: 计算机实现的方法,数据处理系统和计算机程序产品,以便以合规性示范的目的,以安全,受控的方式有限地访问联盟合作伙伴的审核日志。 审核数据的请求由联合环境中的合作伙伴接收。 伙伴验证请求,并使用本地审计日志存储区的本地参数请求本地报告。 合作伙伴随后根据本地报告建立回应。

    Method and system for peer-to-peer authorization
    5.
    发明授权
    Method and system for peer-to-peer authorization 失效
    用于对等授权的方法和系统

    公开(公告)号:US07877480B2

    公开(公告)日:2011-01-25

    申请号:US12183251

    申请日:2008-07-31

    IPC分类号: G06F15/173 G06F15/16

    摘要: An authorization mechanism within a peer-to-peer network is presented. A central server that operates a centralized data repository search engine within a peer-to-peer network performs authentication and authorization operations with respect to users that access its services. A user at a peer node reviews peer-to-peer search results that have been gathered and returned by the centralized search engine. When the user desires to retrieve a file from another peer node, the user's peer node must obtain an authorization token from the central server, which authenticates the user or has previously authenticated the user. The user's peer node then presents the authorization token along with a request to retrieve the file from the other peer node. After verifying the authorization token, the other peer node responds with the requested file. If the other peer node cannot verify the authorization token, then the other peer node denies access to the file.

    摘要翻译: 提出了对等网络中的授权机制。 操作对等网络中的集中式数据存储库搜索引擎的中央服务器对访问其服务的用户执行认证和授权操作。 对等节点的用户会检查由集中式搜索引擎收集和返回的对等搜索结果。 当用户期望从另一个对等节点检索文件时,用户的对等节点必须从中央服务器获取授权令牌,该授权令牌对用户进行身份验证或者先前已经对用户进行身份验证。 然后,用户的对等节点显示授权令牌以及从另一个对等节点检索文件的请求。 验证授权令牌后,其他对等节点用所请求的文件进行响应。 如果其他对等节点无法验证授权令牌,则其他对等节点拒绝对该文件的访问。

    Specializing Support For A Federation Relationship
    6.
    发明申请
    Specializing Support For A Federation Relationship 失效
    专业支持联邦关系

    公开(公告)号:US20090259753A1

    公开(公告)日:2009-10-15

    申请号:US12481007

    申请日:2009-06-09

    IPC分类号: G06F15/16

    CPC分类号: H04L63/0815 H04L67/30

    摘要: The invention provides federated functionality within a data processing system by means of a set of specialized runtimes, which are instances of an application for providing federation services to requesters. Each of the plurality of specialized runtimes provides requested federation services for selected ones of the requestors according to configuration data of respective federation relationships of the requestors with the identity provider. The configuration data is dynamically retrieved during initialization of the runtimes which allows the respective_runtime to be specialized for a given federation relationship. Requests are routed to the appropriate specialized runtime using the first requestor identity and the given federation relationship. The data, which describes each federation relationship between the identity provider and each of the plurality of requestors, is configured prior to initialization of the runtimes.

    摘要翻译: 本发明通过一组专用运行时提供数据处理系统内的联合功能,这是一组向需求者提供联合服务的应用的实例。 多个专用运行时间中的每一个根据请求者与身份提供者的各自的联合关系的配置数据,为所选请求者提供所请求的联合服务。 在运行时的初始化期间动态地检索配置数据,这允许相应的运行时间针对给定的联合关系而专门化。 请求使用第一请求者标识和给定的联合关系路由到适当的专用运行时。 在初始化运行时之前配置描述身份提供者与多个请求者中的每一个之间的每个联合关系的数据。

    Method and system for encrypting JavaScript object notation (JSON) messages
    7.
    发明授权
    Method and system for encrypting JavaScript object notation (JSON) messages 有权
    用于加密JavaScript对象符号(JSON)消息的方法和系统

    公开(公告)号:US09461817B2

    公开(公告)日:2016-10-04

    申请号:US12356305

    申请日:2009-01-20

    IPC分类号: H04L9/32 G06F21/00 H04L9/08

    摘要: The confidentiality of JavaScript Object Notation (JSON) message data is secured using an encryption scheme. The encryption scheme implements a JSON encryption syntax, together with a set of processing rules for creating encrypting arbitrary data in JSON messages in a platform/language independent manner. A method for encrypting a data item in a JSON message begins by applying an encryption method and a key to the data item to generate a cipher value. A data object is then constructed that represents an encryption of the data item. The data item in the JSON message is then replaced with the data object, and the resulting modified JSON message is then output from a sending entity. At a receiving entity, information in the data object is used to re-generate the data item, which is then placed back in the original message.

    摘要翻译: 使用加密方案保护JavaScript对象符号(JSON)消息数据的机密性。 加密方案实施JSON加密语法,以及一组处理规则,用于以平台/语言独立的方式在JSON消息中创建加密任意数据。 用于加密JSON消息中的数据项的方法首先通过对数据项应用加密方法和密钥来生成密码值。 然后构建表示数据项的加密的数据对象。 然后将JSON消息中的数据项替换为数据对象,然后从发送实体输出生成的修改后的JSON消息。 在接收实体,数据对象中的信息用于重新生成数据项,然后将其放回到原始消息中。

    Token caching in trust chain processing
    8.
    发明授权
    Token caching in trust chain processing 有权
    令牌缓存在信任链处理中

    公开(公告)号:US09325695B2

    公开(公告)日:2016-04-26

    申请号:US12327899

    申请日:2008-12-04

    IPC分类号: H04L29/06

    CPC分类号: H04L63/0815 H04L63/0823

    摘要: A method, system, and computer usable program product for token caching in a trust chain processing are provided in the illustrative embodiments. An information in a token associated with a first request is mapped. A determination is made whether a requester of the first request has provided a constraint in the first request, the constraint concerning the token, the constraint forming a client constraint. The client constraint is stored. The information and the mapped information is stored, forming stored information. The token is received in a second request. The stored information is reused if the client constraint allows reusing the stored information. A further determination may be made whether a target system receiving the mapped information has provided a server constraint, the second constraint concerning the mapped information, the second constraint forming a server constraint. The stored information may be reused if the server constraint allows reusing the stored information.

    摘要翻译: 在说明性实施例中提供了用于信任链处理中的令牌缓存的方法,系统和计算机可用程序产品。 与第一个请求相关联的令牌中的信息被映射。 确定第一请求的请求者是否在第一请求中提供约束,关于令牌的约束,形成客户约束的约束。 客户端约束被存储。 存储信息和映射信息,形成存储的信息。 令牌在第二个请求中被接收。 如果客户端约束允许重用存储的信息,则存储的信息被重新使用。 可以进一步确定接收映射信息的目标系统是否提供了服务器约束,关于映射信息的第二约束,形成服务器约束的第二约束。 如果服务器约束允许重用存储的信息,则可以重新使用所存储的信息。

    Token mediation service in a data management system
    9.
    发明授权
    Token mediation service in a data management system 有权
    令牌中介服务在数据管理系统中

    公开(公告)号:US08522335B2

    公开(公告)日:2013-08-27

    申请号:US12628477

    申请日:2009-12-01

    IPC分类号: H04L29/06

    摘要: A method and system for mediating security tokens to authorization data transactions in a data management system. The methods and systems intercept a data request between two applications or services, and validate and translate a security token sent with the data request from a format compatible with the first application or service to a format compatible with the second application or service.

    摘要翻译: 一种用于在数据管理系统中调解安全令牌以授权数据事务的方法和系统。 方法和系统拦截两个应用程序或服务之间的数据请求,并且将从数据请求发送的安全令牌从与第一应用程序或服务兼容的格式验证并转换为与第二应用程序或服务兼容的格式。

    Federated single sign-on (F-SSO) request processing using a trust chain having a custom module
    10.
    发明授权
    Federated single sign-on (F-SSO) request processing using a trust chain having a custom module 有权
    使用具有自定义模块的信任链的联合单点登录(F-SSO)请求处理

    公开(公告)号:US08141139B2

    公开(公告)日:2012-03-20

    申请号:US11939749

    申请日:2007-11-14

    摘要: Federated single sign on (F-SSO) uses a token service that fulfills requests by executing a module chain comprising a set of modules. F-SSO runtime processing is enhanced by enabling a federated entity user to define a custom module to include in the chain. The custom module includes one or more name-value pairs, wherein a given name-value pair has a value that may be validated against an entity-defined rule. The rule is determined during the processing of the custom module based on one or more invocation parameters of the module chain. In a runtime operation, F-SSO begins in response to receipt of a token. In response, the processing of the module chain that includes the custom module is initiated. During processing of the custom module, an attempt is made to validate the value of a name-value pair based on the rule. If the value of the name-value pair based on the rule can be validated, processing of the module chain continues. This approach enables finer granularity on the information that can be asserted or required as part of an F-SSO flow.

    摘要翻译: 联合单点登录(F-SSO)使用通过执行包括一组模块的模块链来满足请求的令牌服务。 通过使联合实体用户能够定义要包含在链中的自定义模块来增强F-SSO运行时处理。 自定义模块包括一个或多个名称 - 值对,其中给定的名称 - 值对具有可以根据实体定义的规则被验证的值。 在根据模块链的一个或多个调用参数处理自定义模块期间确定规则。 在运行时操作中,F-SSO响应于令牌的接收而开始。 作为响应,启动了包含定制模块的模块链的处理。 在自定义模块的处理期间,尝试根据规则验证名称 - 值对的值。 如果可以验证基于规则的名称 - 值对的值,则模块链的处理将继续进行。 这种方法可以在作为F-SSO流程的一部分可以被断言或需要的信息上实现更精细的粒度。